Junglewise Threat Intelligence

CVE-2026-39571: Themefic Instantio sensitive data exposure

CVE-2026-39571 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Vendors: Themefic.

Executive brief

Themefic Instantio, a WordPress plugin used to streamline the WooCommerce checkout process, contains a vulnerability that exposes sensitive system information. An unauthorized attacker could access data that is normally restricted, potentially gaining insights into the system's configuration or internal state. This information could be used to facilitate more complex attacks against the website.

Technical details

The Themefic Instantio plugin for WordPress (up to version 3.3.30) is vulnerable to CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere). The vulnerability allows an unauthenticated remote attacker to retrieve sensitive data embedded within the application's responses or system environment. This occurs because the software does not properly restrict access to sensitive system-level information from the network-reachable control sphere. Attackers can exploit this to gain technical details about the environment, which may assist in further exploitation. The issue is resolved in version 3.3.31.

Affected products

  • Themefic Instantio <= 3.3.30

Timeline

  • 2026-02-23: other: Vulnerability reported by researcher
  • 2026-03-25: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published
  • 2026-03-25: patched: Version 3.3.31 released to address the issue

References